Cross-Site Scripting Vulnerability in Satori Library by Vercel
CVE-2026-94545
Key Information:
Badges
What is CVE-2026-94545?
CVE-2026-94545 is a cross-site scripting (XSS) vulnerability discovered in the Satori library developed by Vercel, which is utilized for converting HTML and CSS into SVG (Scalable Vector Graphics) format. This vulnerability exists in versions of Satori from 0.0.27 up to, but not including, 0.33.5. The core issue arises from the improper escaping of certain values within the generated SVG output by Satori. Attackers can exploit this flaw by injecting crafted input that may be interpreted as SVG markup, potentially leading to unintended execution of scripts within the context of a victimβs browser session when they render the SVG. This opens up organizations to a variety of attacks, such as data leakage, session hijacking, or manipulation of the display content. Due to the prevalence of SVG usage in web applications, this vulnerability, if left unaddressed, could severely compromise the security of applications leveraging the Satori library.
Potential impact of CVE-2026-94545
-
User Data Exposure: Attackers could leverage this vulnerability to execute scripts that extract sensitive information from users, such as authentication tokens or personal data, undermining user privacy and data integrity.
-
Session Hijacking: By executing malicious scripts through the flawed SVG rendering process, attackers may gain unauthorized access to user accounts and sessions, allowing them to perform actions on behalf of legitimate users.
-
Content Manipulation: The exploitation potential allows adversaries to alter the visual content presented to users, which can be used to conduct phishing attacks or distribute malware, damaging both user trust and organizational reputation.
Affected Version(s)
next >= 16.2.0, < 16.3.6
satori >= 0.0.27, < 0.33.5
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- π
Vulnerability started trending
- π‘
Public PoC available
- πΎ
Exploit known to exist
Vulnerability published
Vulnerability Reserved